MAL-2026-13595
Dashboard / Malicious Package / MAL-2026-13595
MAL-2026-13595
Summary: Malicious code in dolyame-ui-postcsscustomproperties (npm)
Details: Source: amazon-inspector (a8be08d3eb5601ca7f7b5f74c34e3fd0ebba91f0b72dea8ab4b0642bb9695c0c) On require() of the package, _shim.js and lib/telemetry.js (reached via the main entry) select a platform-specific payload, download a binary over HTTPS from string-split Cloudflare Workers hosts (oob-worker.cf100-416.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf99-9b3.workers.dev), and fall back to reassembling base64 chunks retrieved from DNS TXT queries against *.sdk.dl.wel1.ru. The fetched bytes are written to /var/tmp/.cache_<hex> on Unix or %TEMP%\dotnet_diag_<hex>.exe on Windows, chmod 0755, and detached-spawned via /bin/sh -c or cmd.exe. Destination hosts, module names, and API names are string-split and reassembled at runtime (require("child_"+"process"), fs["chmod"+"Sync"], hostnames joined from arrays) to defeat static inspection. The package name typosquats postcss-custom-properties and the dropper is labelled as an 'Analytics SDK' / 'telemetry' module.
Affected packages
Package
Name: dolyame-ui-postcsscustomproperties
Purl: pkg:npm/dolyame-ui-postcsscustomproperties
Affected ranges
Type: N/A
Events:
